CVE-2025-22251: Fortinet FortiOS
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to inject unauthorized sessions via crafted FGSP session synchronization packets.
Affected products
- Fortinet FortiOS: from 6.4.0, before 7.4.6 (fixed in 7.4.6); version 7.6.0 only
Published 2025-06-10. Last modified 2026-06-17.